validQueryText reports whether every key and value a handler could read out of this raw query string is bindableText. WHAT IT CHECKS AGAINST. url.ParseQuery is the same call r.URL.Query() makes, so the pairs checked in the decode step are exactly the pairs a handler can see — there is no equivalent
(rawQuery string)
| 324 | // introduce anything, and none of these can put a NUL into a string that |
| 325 | // had none. |
| 326 | func validQueryText(rawQuery string) bool { |
| 327 | if rawQuery == "" { |
| 328 | return true |
| 329 | } |
| 330 | if !bindableText(rawQuery) { |
| 331 | return false |
| 332 | } |
| 333 | if !strings.Contains(rawQuery, "%") { |
| 334 | return true |
| 335 | } |
| 336 | q, _ := url.ParseQuery(rawQuery) |
| 337 | for key, values := range q { |
| 338 | if !bindableText(key) { |
| 339 | return false |
| 340 | } |
| 341 | for _, v := range values { |
| 342 | if !bindableText(v) { |
| 343 | return false |
| 344 | } |
| 345 | } |
| 346 | } |
| 347 | return true |
| 348 | } |
| 349 | |
| 350 | // unicodeEscapePrefix is the four bytes that begin any JSON \u escape for a |
| 351 | // character below U+0100. Built from bytes rather than written as a literal, |